The FFIEC has recognized that cyber threats have become increasingly sophisticated and more common. To address the risk to financial institutions, the FFIEC developed the cybersecurity assessment tool, which evaluates a financial institution’s inherent risk profile and cybersecurity maturity. The inherent risk profile considers five categories including technologies and connection types, delivery channels, online and mobile products and technology services, organizational characteristics, and external threats. The tool is used to assess the risk level (from least to most) within specific areas for each category. Cybersecurity maturity evaluates five areas including cyber risk management and oversight, threat intelligence and collaboration, cybersecurity controls, external dependency management, and cyber incident management and resilience—all along various assessment factors.
The FDIC Advisory Committee will discuss the assessment tool during its July 10 meeting, which can be accessed by live webcast on the FDIC website. The cybersecurity assessment tool itself is available on the FFIEC website.
S.P. Slaughter
Follow me on Twitter: @SP_Slaughter
Related Attorneys
- Partner